In part 2 of this interview, we cover:
- Reasoning behind why the specific account lockout and password policy settings were chosen in the guide
- General tips (using the appendix when you have a problem and check out the Threats and countermeasures guide)
- How to the guide helps implement the granular AD auditing capabilities in WS 2008.
- Demo of the security solution accelerator
For part 1, click here.
You can download the Windows Server 2008 security guide here.
In part 1 of 2 for this interview with the program managers of the security guides Jose Maldonado and Vlad Pigin, and test lead Bora Gaurav we cover a number of topics including:
- What the differences are between the 2003 security guide and the new Server 2008 security guide
- What are some of the "deal killers" for most people to be able to run in the specialized security limited functionality (SSLF) mode versus the Enterprise Client mode (EC)
- Briefly go through the basic steps to implement
- Establish an acceptable security baseline (EC or SSLF)
- Run the GPO accelerator tool to deploy the baseline
- Deploy the server roles (if you haven't already done this)
- Secure the individual roles using SCW / GPO accelerator tool / guide & checklist
- How to implement the guide using a different OU structure than mentioned in the guide.
You can download the Windows Server 2008 security guide here.